Integrations
Connect the agents you already run
Vidimus reaches your agent through the interface it already exposes. Paste a request that already works, check that the agent answers, then run the tests. Nothing to install.
- Wire protocols
- Authentication methods
- Registry connectors
- Software to install
Three steps, then the run
The same flow for every agent, whatever built it.
Where is the agent
A reachability check gives a plain verdict, and the fix when something blocks. Protocol detection sends at most 12 requests, and shows you each one.
How to call it
Paste a request that already works: a curl command, a HAR file, a Postman request, JavaScript fetch, Python requests or a raw HTTP exchange. Or pick a platform, or fill it in by hand.
Check that it answers
One real message goes through the same code a test run uses. The connection is saved as verified, with the name of the person and the time.
The interfaces Vidimus speaks
Seven wire protocols, with ready-made settings for the platforms banks and insurers run.
| Interface | Typical platforms |
|---|---|
| JSON over HTTP | n8n, Make, a service your team wrote, an API gateway in front of either |
| JSON over HTTP, with tool calls in the reply | In-house agents that return the tools they called with the reply |
| OpenAI-compatible chat completions | Azure OpenAI, vLLM, LiteLLM, an Amazon Bedrock gateway, a Databricks gateway |
| OpenAI Responses API | OpenAI, Azure AI Foundry |
| Microsoft Direct Line (Copilot Studio) | Microsoft Copilot Studio, Power Automate, Azure Bot Service |
| A2A | Google ADK, any A2A 1.0, 0.3 or 0.2 server |
| MCP | an MCP server behind your gateway, a tool server your platform team runs |
| Streaming (server-sent events) | Chat front ends that stream the answer |
| Event or webhook (back-office agent) | Back-office agents started by a queue message or a webhook |
JSON over HTTP
- Typical platforms
- n8n, Make, a service your team wrote, an API gateway in front of either
JSON over HTTP, with tool calls in the reply
- Typical platforms
- In-house agents that return the tools they called with the reply
OpenAI-compatible chat completions
- Typical platforms
- Azure OpenAI, vLLM, LiteLLM, an Amazon Bedrock gateway, a Databricks gateway
OpenAI Responses API
- Typical platforms
- OpenAI, Azure AI Foundry
Microsoft Direct Line (Copilot Studio)
- Typical platforms
- Microsoft Copilot Studio, Power Automate, Azure Bot Service
A2A
- Typical platforms
- Google ADK, any A2A 1.0, 0.3 or 0.2 server
MCP
- Typical platforms
- an MCP server behind your gateway, a tool server your platform team runs
Streaming (server-sent events)
- Typical platforms
- Chat front ends that stream the answer
Event or webhook (back-office agent)
- Typical platforms
- Back-office agents started by a queue message or a webhook
Interfaces Vidimus connects to today, and the platforms that usually sit behind them.
Multi-turn tests carry the conversation: message history, A2A context and Direct Line conversation.
On request
Agents hosted on these platforms: tell us, and we build the adapter.
Authentication
Six ways to authenticate, from an open test endpoint to mutual TLS.
- None
- An open endpoint, such as a test environment.
- Header
- A bearer token or an API key, in the header your gateway expects.
- API key in the address
- An API key in the query string, as some gateways require.
- OAuth 2.0 client credentials
- Client credentials, with audience or resource, in basic or body form. The token is fetched and cached for you.
- Google service account
- A Google service account, exchanged for an access token.
- Mutual TLS
- A client certificate, for mutual TLS.
Credentials sit in a vault; Vidimus stores only their reference. A secret found in a pasted command is never saved unless you type it again.
What a test run sends
What your agent receives, and what Vidimus keeps.
| Per run | What to expect |
|---|---|
| Tests per run | Up to 150, trimmed by severity above that. The trimmed tests are named. |
| Attempts per test | 10, so a run makes at most 1,500 attempts. A multi-turn attempt sends one message per turn, up to five, and Direct Line and A2A poll until the reply arrives. |
| Pace | A limited number of requests at once, and a rate limit per agent. |
| Stopping | Any run can be cancelled at any time. |
| Typical duration | 28 tests, 280 attempts: 22 minutes in our reference run. |
| What is recorded | Every prompt, reply and tool call, kept in the EU. |
| Tool calls | Read from the reply, the tool log or the event trace. A call to a tool the agent never declared is a finding. |
| Sub-agents | Your orchestrator (LangGraph, AutoGen, CrewAI) can push traces to a webhook for each agent, matched to each test. |
Tests per run
- What to expect
- Up to 150, trimmed by severity above that. The trimmed tests are named.
Attempts per test
- What to expect
- 10, so a run makes at most 1,500 attempts. A multi-turn attempt sends one message per turn, up to five, and Direct Line and A2A poll until the reply arrives.
Pace
- What to expect
- A limited number of requests at once, and a rate limit per agent.
Stopping
- What to expect
- Any run can be cancelled at any time.
Typical duration
- What to expect
- 28 tests, 280 attempts: 22 minutes in our reference run.
What is recorded
- What to expect
- Every prompt, reply and tool call, kept in the EU.
Tool calls
- What to expect
- Read from the reply, the tool log or the event trace. A call to a tool the agent never declared is a finding.
Sub-agents
- What to expect
- Your orchestrator (LangGraph, AutoGen, CrewAI) can push traces to a webhook for each agent, matched to each test.
The traffic of one test run, and what is recorded.
Your inventory, synced
Vidimus pulls agents from where they are already registered, every six hours or on demand. A person’s registration is never overwritten: a change opens a review item.
- Google Gemini Enterprise Agent Registry
- Microsoft Agent 365 (Entra Agent ID)
- Amazon Bedrock AgentCore
- A2A well-known discovery
- MCP registry
- agentregistry (aregistry.ai, Apicurio)
Or push agents yourself: POST /api/v1/registry/agents, described in OpenAPI, or a CSV or JSON upload. The registry API
Already keep the inventory in a GRC suite? How the two fit together: Vidimus compared with GRC suites and red teaming.
Registration pre-filled from your code
Point Vidimus at a GitLab or Bitbucket repository, or a folder read in your browser. It proposes answers with file and line, including system-prompt wording that bears on Article 50 or Article 5. A person accepts or rejects each one.
Agents that never leave your network
Run Vidimus inside your estate: self-hosted deployment on Enterprise, on request. The tests then reach the agent from inside your network.
Integration questions
Do we need to install anything?
No. Vidimus calls your agent from outside, through the interface it already exposes, the way a user does.
Can you test our production endpoint?
Yes. A run is capped at 150 tests of 10 attempts, throttled per agent, and can be cancelled at any time. Use a test endpoint if you prefer. Credentials sit in a vault; prompts and replies stay in the EU.
Our agent is behind a firewall. Can you reach it?
Run Vidimus inside your estate: self-hosted deployment on Enterprise, on request. The tests then reach the agent from inside your network. There is no fixed address range to allow.
Does Vidimus see our system prompt?
Only what you choose to share. The tests reach the agent from outside, like a user. If you use the code scan, it proposes the prompt wording that bears on Article 50 or Article 5, and you accept or reject each item. The judge never receives your system prompt.
Pilot
Connect one agent, see its evidence
A pilot starts with one request that already works against one of your agents, and ends with a signed evidence pack.
Pilot
- One agent, end to end
- Ends with a walkthrough of the evidence pack with your risk and compliance leads
- Credited against the first year